Security & trust

Built for sensitive governance records, not casual collaboration.

BoardConcur avoids overclaiming certifications at the Public Alpha stage. The current foundation emphasizes locked-down client access, server-mediated writes, Firebase authentication, and a clear path to tenant and role enforcement.

Trust foundations

The Public Alpha establishes safe defaults and documents the controls that will deepen as the logged-in product is built.

Authentication

Firebase Authentication provides the Public Alpha identity foundation.

Google Sign-In

Google provider support gives board and management users a familiar sign-in path once authorized domains are configured.

MFA-ready architecture

Firebase Auth can support MFA expansion after tenant invitations and role policy are introduced.

Role-based access

The data model is being prepared for association, board, committee, manager, management company, and advisor roles.

Tenant isolation

Firestore rules are locked down by default until tenant-scoped authorization is implemented.

Audit trails

Future Matter events will preserve important changes, visibility decisions, certifications, and record updates.

Server-side Firestore writes

Demo requests are written by the Next.js server route using the Admin SDK, not by public browser clients.

No public direct-write demo requests

Firestore rules explicitly deny direct client reads and writes to demoRequests.

Workspace-ready file model

The product is being designed to map Google Workspace files to Matters, roles, tenants, and records.

AI permission boundaries

Future AI features should answer only from sources the signed-in user is authorized to access and should cite source records.

BoardConcur

Ready to run the board, not the inbox?

See how BoardConcur can turn scattered emails, attachments, and follow-ups into a structured board record.